Iain Mulholland, senior director of Security Engineering at Google Cloud, explains the approach to security engineering and the importance of secure by design principles.
Google Cloud's security team partners with product team software engineers to ship secure software while maintaining product-release velocity.
The team emphasizes secure-by-design architectures to nullify vulnerabilities and attack vectors in modern security landscapes.
Threat modeling practice is utilized to analyze potential threats in the design phase and ensure products are secure by design.
Google Cloud engineers work on protecting against various threats like outbound network attacks, resource misuse, and content-based threats.
AI, data science, and analytics solutions are employed to predict user behavior, identify risky security patterns, and enhance threat detection and mitigation.
The team focuses on finding vulnerabilities before attackers by considering the entire cloud as an attack surface and chaining vulnerabilities in novel ways.
Collaboration with the Vulnerability Rewards Program aids in responding to threats and implementing remediation strategies.
By embedding security into engineering processes early on, Google Cloud enhances decision-making confidence and business resilience.
Subscribe to the Cloud CISO Perspectives newsletter for security-related updates from Google Cloud twice a month.